Together with @bzvr_, @2igosha and Anton Kargin, we identified that the DAEMON Tools software has been compromised in a complex supply chain attack since April 8. We see thousands of infections across 100+ countries. If you use DAEMON Tools, run a malware scan immediately! [1/7]
The secret's out.🤫
Introducing THE https://t.co/iULfuMrtEd COMMUNITY 👾
Inside:
• 0-day vuln deep dives from @xint_official, @stdoutput, @pspaul95 & more...
• Access to events & a network of world-class hackers
• CTFs with prizes
Join now :)
🚨 BREAKING: Wiz Research discovered Remote Code Execution on https://t.co/SvN2lGsnbO with a single git push
The flaw in @github allowed unauthorized access to millions of repositories belonging to other users and organizations 🤯
🔥🐉 New GOAD Lab: DRACARYS
I’ve just released a new free lab environment on GOAD: DRACARYS.
The challenge includes 3 VMs and the objective is simple:
Start with no authentication and work your way up to Domain Admin.
Have fun exploiting it! 🔥🐉
https://t.co/TkbVEIxyyX
@Jhaddix How dare you earn a living. Clearly no one else shares their opinion. Ill never forget meeting you at Defcon 22, and you gave me a copy and course materials; I thought Holy cow thats amazing!
OpenClaw can now scrape any website without getting blocked - zero bot detection, bypasses Cloudflare natively, 774x faster than BeautifulSoup.
No selector maintenance. No workarounds. Just data.
THIS IS AN UNFAIR ADVANTAGE AND IT'S FULLY OPEN SOURCE.
Dropping new LOLBin/LOLBAS inspired project today called LOLGlobs, to document some cool ways of commandline evasion using wildcards and some other obfuscation techniques that go beyond B64 encoding: https://t.co/weesvN45Vd
ASN/CIDR lookups are massively underrated for recon.
Start with a company name. Find all their assets. Get instant ASN to CIDR lookups, IP/DNS/ORG resolution, and JSON/CSV output 👇
https://t.co/IisZfi1WY3
[New blog post] Analyzing #MicrosoftEntra 🤖 Workload Identity Activity Through 🪙 Token-Based Hunting
I’ve published a #KQL function to hunt activities by tokens from non-human identities and share some experimental queries and insights in this article.
https://t.co/XbW0rQ7ekR